SourceCodester Open Source Clinic Management System是SourceCodester开源的一个开源诊所管理系统。 SourceCodester Open Source Clinic Management System 1.0版本存在注入漏洞,该漏洞源于对文件/doctor.php中参数doctorname的错误操作导致SQL注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SourceCodester | Open Source Clinic Management System | 1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2025-5755 | 7.3 HIGH | SourceCodester Open Source Clinic Management System email_config.php sql injection |
| CVE-2025-5716 | 7.3 HIGH | SourceCodester Open Source Clinic Management System login.php sql injection |
| CVE-2025-5712 | 7.3 HIGH | SourceCodester Open Source Clinic Management System appointment.php sql injection |
| CVE-2025-5728 | 6.3 MEDIUM | SourceCodester Open Source Clinic Management System manage_website.php unrestricted upload |
| CVE-2025-5727 | 2.4 LOW | SourceCodester Student Result Management System Announcement Page announcement cross site |
| CVE-2025-5726 | 2.4 LOW | SourceCodester Student Result Management System Division System Page division-system cross |
| CVE-2025-5725 | 2.4 LOW | SourceCodester Student Result Management System Grading System Page grading-system cross s |
| CVE-2025-5724 | 2.4 LOW | SourceCodester Student Result Management System Subjects Page subjects cross site scriptin |
| CVE-2025-5723 | 2.4 LOW | SourceCodester Student Result Management System Classes Page classes cross site scripting |
| CVE-2025-5722 | 2.4 LOW | SourceCodester Student Result Management System Add Academic Term terms cross site scripti |
| CVE-2025-5721 | 2.4 LOW | SourceCodester Student Result Management System Profile Setting Page update_profile cross |
No comments yet